Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1280 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.53% | — | Ebyte Configuration UtilityAI | 31/8/2026 | 1/9/2026 | The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing… | |
| Aplazada | Baja (1.9) | 0.16% | — | LatencyutilsAI | 31/8/2026 | 31/8/2026 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a manipulation can lead to memory corruption. The attack needs to be launched… | |
| Aplazada | Baja (3.7) | 0.41% | — | Apache Appsamurai UtilAI | 23/8/2026 | 26/8/2026 | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, each over a fresh Time::HiRes reading formatted to six decimal places, the running digest, and the process… | |
| Aplazada | Alta (7.3) | 0.12% | — | Remote Utilities HostAI | 21/8/2026 | 26/8/2026 | Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\SYSTEM loads DLLs from this directory. The… | |
| Pendiente de análisis | Media (5.6) | 0.15% | — | AMD Ryzen Master Utility DriverAI | 11/8/2026 | 12/8/2026 | A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability | |
| Pendiente de análisis | Media (4.4) | 0.11% | — | PolicycoreutilsAI | 7/8/2026 | 1/9/2026 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race… | |
| Analizada | Alta (7.5) | 0.51% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | |
| Analizada | Alta (7.5) | 0.51% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. | |
| Analizada | Crítica (9.1) | 0.59% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | |
| Analizada | Crítica (9.1) | 0.46% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.38% | — | Apache Apr-util | 6/8/2026 | 29/9/2026 | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to… | |
| Analizada | Alta (8.7) | 0.49% | — | Bouncycastle Bc-javaBouncycastle Bcutil-fipsBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series). | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | GNU BinutilsAI | 29/7/2026 | 30/7/2026 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via… | |
| Pendiente de análisis | Alta (7.6) | 0.35% | — | SG3 UtilsAI | 28/7/2026 | 1/10/2026 | A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database.… | |
| Pendiente de análisis | Media (5.6) | 0.15% | — | GNU BinutilsAI | 27/7/2026 | 1/9/2026 | A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an… | |
| Analizada | Media (4.6) | 0.17% | — | GNU Coreutils | 24/7/2026 | 26/8/2026 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an… | |
| Aplazada | Alta (7.3) | 0.17% | — | Geovision Gv-ip Device UtilityAI | 24/7/2026 | 30/7/2026 | A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. | |
| Analizada | Baja (1.8) | 0.19% | — | GNU Coreutils | 24/7/2026 | 2/10/2026 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent… | |
| Aplazada | Media (6.8) | 0.14% | — | Selinux PolicycoreutilsAI | 23/7/2026 | 23/7/2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10. | |
| Aplazada | Media (5.8) | 0.10% | — | Selinux PolicycoreutilsAI | 23/7/2026 | 23/7/2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10. | |
| Pendiente de análisis | Baja (2.1) | 0.33% | — | GNU DiffutilsAI | 22/7/2026 | 27/7/2026 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Utilities Network Management System | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability… | |
| Analizada | Media (4.3) | 0.27% | — | Oracle Utilities Network Management System | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and 25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability… | |
| Analizada | Media (4.6) | 0.21% | — | Oracle Utilities Network Management System | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7 and 25.12.0.0.0. Easily exploitable vulnerability allows low… | |
| Aplazada | Alta (7.2) | 0.48% | — | Nevware21 Ts-utilsAI | 21/7/2026 | 23/7/2026 | @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype).… |